2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28034MEDIUM6.1WordPress before 5.5.2 allows XSS associated with global variables.
CVE-2020-28033HIGH7.5WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam ...
CVE-2020-28032CRITICAL9.8WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-28031MEDIUM4.3eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenti...
CVE-2020-28030HIGH7.5In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by co...
CVE-2020-28002MEDIUM5.3In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty val...
CVE-2020-27992HIGH7.8Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Won...
CVE-2020-27982MEDIUM6.1IceWarp 11.4.5.0 allows XSS via the language parameter.
CVE-2020-27708HIGH7.8A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either...
CVE-2020-27359MEDIUM5.4A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScrip...
CVE-2020-27358MEDIUM4.3An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export...
CVE-2020-25689MEDIUM6.5A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in ...
CVE-2020-24881CRITICAL9.8SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
CVE-2020-23639CRITICAL9.8A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a r...
CVE-2020-15914MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allo...
CVE-2020-14750CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions...
CVE-2020-14425HIGH7.8Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe...
CVE-2020-10937HIGH7.5An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverag...
CVE-2020-3704HIGH7.5u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device ma...
CVE-2020-3703CRITICAL9.8u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r...
CVE-2020-3696HIGH7.8u'Use after free while installing new security rule in ipcrtr as old one is deleted and this rule could still be in use ...
CVE-2020-3694HIGH7.8u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapd...
CVE-2020-3693HIGH7.8u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snap...
CVE-2020-3692CRITICAL9.8u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input valid...
CVE-2020-3690HIGH7.8u'Due to an incorrect SMMU configuration, the modem crypto engine can potentially compromise the hypervisor' in Snapdrag...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now